Техническая информация
- %APPDATA%\microsoft\windows\start menu\programs\startup\<Имя файла>.exe
- C:\users\public\dbg.zip
- http://14#.#2.55.237/dbg.zip
- '%WINDIR%\syswow64\cmd.exe' /c powershell -Command Add-MpPreference -ExclusionPath "%APPDATA%\prgrm"
- '%WINDIR%\syswow64\cmd.exe' /c powershell -Command Add-MpPreference -ExclusionPath "C:\Users\Public"
- '%WINDIR%\syswow64\cmd.exe' /c powershell -Command Add-MpPreference -ExclusionExtension ".exe"
- '%WINDIR%\syswow64\cmd.exe' /c powershell -Command Add-MpPreference -ExclusionProcess "EthDcrMiner64.exe"
- '%WINDIR%\syswow64\cmd.exe' /c powershell -Command Add-MpPreference -ExclusionProcess "EthDcrMiner64"
- '%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' -Command Add-MpPreference -ExclusionPath "C:\Users\Public"
- '%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' -Command Add-MpPreference -ExclusionProcess "EthDcrMiner64.exe"
- '%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' -Command Add-MpPreference -ExclusionExtension ".exe"
- '%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' -Command Add-MpPreference -ExclusionProcess "EthDcrMiner64"
- '%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' -Command Add-MpPreference -ExclusionPath "%APPDATA%\prgrm"